Skip to content
Denial of Service Vulnerability in Ubuntu dpkg Tool

Denial of Service Vulnerability in Ubuntu dpkg Tool

First seen 7 May 2026, 21:08 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 8, 2026 at 21:05 UTC
  • Denial of service vulnerability affects Ubuntu 25.10 and 24.04 LTS.
  • Exploitation could cause dpkg-deb to stop responding when handling crafted .deb files.
  • Users should update to specific dpkg versions to mitigate the risk.

A denial of service vulnerability has been identified in the dpkg tool of Ubuntu versions 25.10 and 24.04 LTS. Discovered by Yashashree Gund, the issue arises when dpkg-deb improperly handles specially crafted zstd-compressed .deb archives. If exploited, this flaw could cause dpkg-deb to stop responding, affecting both users and automated systems. The vulnerability is tracked as CVE-2026-2219 and was published on March 7, 2026. Users are advised to update to the latest package versions to mitigate the risk. The affected versions are dpkg 1.22.21ubuntu3.2 for Ubuntu 25.10 and dpkg 1.22.6ubuntu6.6 for Ubuntu 24.04 LTS. A standard system update will apply the necessary changes.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 137d ago How this analysis works

Timeline

2026-03-07
CVE-2026-2219 published
A denial of service vulnerability in dpkg was disclosed, affecting Ubuntu 25.10 and 24.04 LTS.
Linuxsecurity
2026-05-07
Vulnerability announced
Ubuntu published an advisory regarding the dpkg vulnerability, urging users to update their systems.
Ubuntu

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2026-2219 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed